Administrator Protection Review
ID: e68aabe2-28f8-5b1b-a60d-afabf8a6aec6
STIX ID: report--e68aabe2-28f8-5b1b-a60d-afabf8a6aec6
Feed Name: SpecterOps Blog
This post examines Microsoft's Administrator Protection in Windows 11 (Shadow Admin accounts), describing how shadow accounts are created and how LSASS and Consent.exe issue their tokens. The author demonstrates that existing UAC bypass techniques (LocalAccountTokenFilterPolicy, RunOnce, and UIAccess DLL hijacks) still permit elevation or high-integrity tokens in certain scenarios, highlights allowlist and registry SID link behaviors, and discusses implications for tooling and operational security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
